Dynamics 365 Business Central version 25 introduces a new feature in the environment’s Admin Center panel: Partner Access.
By default, all Dynamics 365 Business Central environments are set up to allow all partner access (very partner with a delegated admin relationship with the customer can access every environment in the tenant).
With this new feature, customer’s internal administrators can use the Partner access settings in the Business Central Admin Center to enable or disable delegated administrators from administering and accessing each environment, or to only allow delegated administrators from specific partner Entra tenants to administer and access a specific environment.
When accessing the Partner Access feature, you have two options:
Here is an example of multiple partner’s selections for a given environment:
Please note that this new setting can only be managed by customer’s internal global administrators.
As a personal recommendation, if you have multiple partners with a GDAP relationship in place with the customer’s tenant, it’s now a best practice to disable the possibility that all partners can access the Business Central environment. You should now set up the environment not to allow access to all partner tenants and then explicitly grant to the partners that you really need the access to the environment. So, the setting should always be the following:
There are also two important hidden aspects to keep in mind related to this feature:
I personally suggest to start using this new feature and change the default behaviour on your environments.
Original Post https://demiliani.com/2024/12/02/dynamics-365-business-central-partner-access-control-to-saas-tenants/